ZeroHour

CVE-2026-69407

mass

Integer Overflow in Microsoft Volume Manager Driver Allows Local Privilege Escalation

CVSS 3.1
7.8 high
EPSS
<1%p25
Published
()
Modified
AI analysis

CVE-2026-69407 is an integer overflow/wraparound flaw (CWE-190) in Microsoft's Volume Manager Driver (volmgr.sys), the Windows kernel component that manages disk volumes. A local attacker with valid low-privileged credentials can trigger the bug by causing the driver's integer arithmetic to wrap, corrupting kernel memory. Successful exploitation yields local privilege escalation, giving the attacker kernel-level access with high impact on confidentiality, integrity, and availability (CVSS 3.1: 7.8). Any Windows system carrying the affected driver is potentially exposed; the available data does not specify affected version ranges, so defenders should consult Microsoft's advisory for build details. There is no known exploitation: the flaw is not in CISA KEV, no public proof-of-concept exists, and EPSS estimates only a 0.3% probability of exploitation in the next 30 days (25th percentile).

What to do: Prioritize applying Microsoft's patch for CVE-2026-69407 when it is available, focusing first on multi-user systems such as servers, terminal servers, and shared workstations where any low-privileged user can attempt exploitation; check Microsoft's advisory for the specific affected builds since version ranges were not provided here. Until patched, restrict local logon rights to trusted users on sensitive systems. Note that no public PoC or in-the-wild exploitation is known, but low EPSS does not reduce the need to patch kernel privilege-escalation bugs.

Affected
Microsoft Volume Manager Driver (Windows kernel driver, volmgr.sys)
Estimated exposure
mass≈1 billion Windows devices (driver ships with Windows) — The Volume Manager driver ships with Windows, which Microsoft reports runs on over a billion active devices, so essentially every Windows installation carries the affected component.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Integer overflow or wraparound in Volume Manager Driver allows an authorized attacker to elevate privileges locally.

Weakness
CWE-190
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.